Back to search
CVE-2022-23410
Published: Feb 14, 2022
Modified: Nov 8, 2024
PUBLISHED
Description
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.
| Vendor | Product | Versions |
|---|---|---|
Axis Communications AB | AXIS IP Utility | affected All version prior to 4.18.0 |
Weaknesses (CWE)
References
https://www.axis.com/files/tech_notes/CVE-2022-23410.pdf
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now